UBUNTU-CVE-2024-53863

Source
https://ubuntu.com/security/CVE-2024-53863
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-53863.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-53863
Related
Published
2024-12-03T17:15:00Z
Modified
2025-01-13T10:26:50Z
Summary
[none]
Details

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. Synapse 1.120.1 addresses the issue by restricting thumbnail generation to images in the following widely used formats: PNG, JPEG, GIF, and WebP. This vulnerability is fixed in 1.120.1.

References

Affected packages

Ubuntu:Pro:18.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse@0.24.0+dfsg-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.19.2+dfsg-6
0.24.0+dfsg-1
0.24.0+dfsg-1ubuntu0.1~esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse@1.11.0-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.0-1
1.4.0-1
1.5.0-1
1.5.1-1
1.6.0-1
1.6.1-1
1.7.0-2
1.7.1-1
1.7.2-1
1.7.3-1
1.8.0-1
1.9.0-1
1.9.1-1
1.10.0-1
1.10.0-2
1.11.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse@1.53.0-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.39.0-1
1.47.0-2
1.47.1-1
1.48.0-1
1.49.0-1
1.49.2-1
1.50.1-1
1.50.2-1
1.51.0-1
1.52.0-1
1.53.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse@1.100.0-1ubuntu1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.100.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / matrix-synapse

Package

Name
matrix-synapse
Purl
pkg:deb/ubuntu/matrix-synapse@1.100.0-1ubuntu1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.90.0-1
1.100.0-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}